Contact Form by WPForms – Drag & Drop Form Builder for WordPress, 968181b8559f062008e22f59da5ad30471dec097
- CVE, Research URL
- Published on
- Sep 18, 2018
- Research Description
- WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.4.8 Contact Form by WPForms – Drag & Drop Form Builder for WordPress <= 1.4.7.2 - Stored Cross-Site Scripting The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tab parameter in versions up to, and including 1.4.7. This makes it possible for lower-privileged attackers to inject arbitrary web scripts in administrative pages that execute whenever a user accesses the page with the stored web scripts.
- Affected versions
-
max 1.4.8.
- Status
-
vulnerable